Export limit exceeded: 398909 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-16542 | 1 Wordpress-extensions | 1 Import And Export Users And Customers | 2026-09-28 | 4.1 Medium |
| The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before requesting it server-side during a CSV import, allowing high-privileged users to perform Server-Side Request Forgery attacks. | ||||
| CVE-2026-92540 | 1 Wordpress-extensions | 1 Import And Export Users And Customers | 2026-09-28 | 7.2 High |
| The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator. | ||||
| CVE-2026-92541 | 1 Wordpress-extensions | 1 Import And Export Users And Customers | 2026-09-28 | 7.2 High |
| The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator. | ||||
Page 1 of 1.